Our position on data protection
Last updated: 8 October 2026
Draft: this text is currently under legal review and may still change.
This English version is a convenience translation. The German version is legally binding.
This page is for data protection officers and anyone who reviews ListPlus before using it. It sums up how we see our role and why. The binding texts are the data processing agreement, the privacy policy and the provider list; this page explains them.
1. A tool, not a database
ListPlus does not collect people and does not sell data. Every search, enrichment or research run happens because a customer triggers it in their workspace, and its result belongs to that workspace alone. Nothing about people is shared between customers; across customers we keep only company data without personal reference, for 30 days. Nobody can search for people on ListPlus without an account.
That is why we see ourselves as the customer's processor (Art. 28 GDPR): the customer decides whether, about whom and for what purpose data is retrieved; we provide the tools. The data providers we query on the customer's behalf are controllers of their own databases and receive only the search key. Whether they count as sub-processors or as independent recipients for that search key is being clarified with our lawyers; until then we treat them like sub-processors (information, right to object).
2. The customer is in control, on the server
The owner of a workspace switches off in the workspace policy whatever their data protection officer does not want: individual data providers, AI features, connected systems, the Inbox address, the Agent API, pipeline emails, the support chat, usage events, contributing to the company cache. Off means: no member and no connected AI system can use the feature, and no data reaches the respective provider — checked on the server, not merely hidden in the interface.
Two features we treat specially. Monitoring people (Watchlist alerts) is off in every workspace until the owner switches it on after a notice of their responsibility; who switched it on and when is recorded. Rating research hits (fit score: how well a hit matches the search description) is on but can be switched off; then nobody is rated.
The policy exports as a text file, and the data protection package (policy, DPA with annexes, provider list, notice for the people in the data, privacy policy) opens as one file to print, or as a 30-day link to pass on.
3. Transparency: one list, every name
Every service provider, data provider and source is in one list with seat, data transmitted and third-country safeguard (listplus.ai/en/subprocessors), which is also Annex 3 of the DPA and the recipients section of the privacy policy — generated from one source so there are never two versions. We also name what is uncomfortable: that public sources such as LinkedIn, Crunchbase, Reddit or X are read by scrapers of a data collection platform, that some providers are in the USA, and what still has to be confirmed with a provider (marked [TO CHECK]).
4. The people in the data
Anyone found or completed through ListPlus finds an explanation addressed to them at listplus.ai/en/contact-data-notice: what ListPlus is, where the data comes from, who receives it, which rights they have. An objection to support@listplus.ai goes, as a checksum, into a suppression list that applies to all customers: the person is no longer retrieved through ListPlus, no longer recorded as a hit and no longer monitored. One limit we name: in a search by name and company only, we learn email address and profile only when the provider answers; we then do not store the result.
5. AI
AI models run only on our servers, never in the browser. Requests to OpenAI go with the “do not store” setting and, according to the provider, without use for training; the judgement model works without storage at the provider. Which data a feature sends is in the privacy policy (section 12), including where it is whole texts. No AI output decides anything with legal effect; all of it is suggestions the user reviews.
6. What we deliberately do not do
- No database of people of our own, no data-broker model — not even for markets where it would be allowed.
- No sharing of personal data between customers.
- No monitoring of people without the customer's explicit activation.
- No person search without an account.
- No use of customer data for training models, neither by us nor by our AI providers.
- No regional “non-EU mode”: as a German GmbH we apply the GDPR to everyone, wherever the customer or the person is.
7. What is still open
We also write down what is not finished. The legal texts are under legal review (draft notice on every page). With some providers, contracts or seat details are still to be confirmed (marked in the provider list). Whether we have to appoint a data protection officer we are clarifying with our lawyers; the features most likely to trigger that duty (monitoring, rating, search without an account) we have put under the customer's instruction or switched off. The Pipedream service, through which connections to CRM systems run, is being replaced. Questions: support@listplus.ai.